questionnaire referred to 14 acts commonly included in notions of cybercrime.3 Responding countries described widespread criminalization of these 14 acts, with the primary exception of SPAM offences and, to some extent, offences concerning computer misuse tools, racism and xenophobia, and online solicitation or ‘grooming’ of children. This reflects a certain baseline consensus on culpable cybercrime conduct. Countries reported few additional crimes, not mentioned in the questionnaire. These mostly concerned computer content, including criminalization of obscene material, online gambling, and online illicit markets, such as in drugs and persons. For the 14 acts, countries reported the use of cyber-specific offences for core cybercrime acts against the confidentiality, integrity and accessibility of computer systems. For other forms of cybercrime, general (non-cyber-specific) offences were used more often. Both approaches were reported, however, for computer-related acts involving breach of privacy, fraud or forgery, and identity offences. While high-level National approaches to criminalization of cybercrime acts consensus exists Illegal access regarding broad areas of Illegal interception criminalization, detailed Illegal interference analysis of the provisions Cyber‐specific Computer misuse tools in source legislation offence Breach of privacy General offence reveals divergent Fraud or forgery approaches. Offences Both Identity offences involving illegal access to Not an offence Copyright or trademark computer systems and offences data differ with respect to SPAM the object of the offence Personal harm (data, system, or Racism and xenophobia information), and Child pornography regarding the Solicitation or grooming criminalization of ‘mere’ Terrorism support offences access or the requirement Source: Study cybercrime questionnaire. Q25‐38. (n=61) for further intent, such as to cause loss or damage. The requisite intent for an offence also differs in approaches to criminalization of interference with computer systems or data. Most countries require the interference to be intentional, while others include reckless interference. For interference with computer data, the conduct constituting interference ranges from damaging or deleting, to altering, suppressing, inputting or transmitting data. Criminalization of illegal interception differs by virtue of whether the offence is restricted to non-public data transmissions or not, and concerning whether the crime is restricted to interception ‘by technical means’. Not all countries criminalize computer misuse tools. For those that do, differences arise regarding whether the offence covers possession, dissemination, or use of software (such as malware) and/or computer access codes (such as victim passwords). From the perspective of international cooperation, such differences may have an impact upon findings of dual-criminality between countries. Several countries have adopted cyber-specific crimes for computer-related fraud, forgery and identity offences. Others extend general provisions on fraud or theft, or rely on crimes covering 3 Illegal access to a computer system; illegal access, interception or acquisition of computer data; illegal data interference or system interference; production, distribution or possession of computer misuse tools; breach of privacy or data protection measures; computer-related fraud or forgery; computer-related identity offences; computer-related copyright and trademark offences; computer-related acts causing personal harm; computer-related acts involving racism or xenophobia; computer-related production, distribution or possession of child pornography; computer-related solicitation or ‘grooming’ of children; and computer-related acts in support of terrorism offences. xx

Select target paragraph3